DSpace 开源软件是一款提供数字资源持久化访问的仓储应用。在版本 7.6.7、8.4、9.3 和 10.0 之前的版本中,当通过 URI 摄入聚合型 ORE 资源(使用 OAI-ORE 收割器)时,ORE 摄入交叉映射(Crosswalk)未对 URI 方案(scheme)进行验证。这可能导致通过类似 的恶意路径实现本地文件包含。攻击者必须已具备 DSpace 集合管理员权限才能实施该攻击。此问题已在版本 7.6.7、8.4、9.3 和 10.0 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49832 | 8.0 HIGH | DSpace: Remote Code Execution (RCE) possible in Velocity Templates used by LDN |
| CVE-2026-49833 | 5.5 MEDIUM | DSpace: Path Traversal possible in LDN message generation |
| CVE-2026-49831 | 5.5 MEDIUM | DSpace: Curation Task Reporter output path is not restricted to trusted directories (Path |
No comments yet